A method and system for handling roaming mobile nodes in a wireless
network. The system uses a Subnet Context Manager to store current
Network session keys, security policy and duration of the session (e.g.
session timeout) for mobile nodes, which is established when the mobile
node is initially authenticated. Pairwise transit keys are derived from
the network session key. The Subnet Context Manager handles subsequent
reassociation requests. When a mobile node roams to a new access point,
the access point obtains the network session key from the Subnet Context
Manager and validates the mobile node by computing a new pairwise
transient key from the network session key.